Tranche 2 customer due diligence in Australia

Tranche 2 customer due diligence in Australia

Customer due diligence for Tranche 2 reporting entities. What to verify, when enhanced CDD applies, and why CDD starts at instruction in property.

AML/CTF Compliance 29 August 2026 10 min read AML Guard

Initial customer due diligence must ordinarily be completed before you provide a designated service under the AML/CTF Act 2006 (Cth). AUSTRAC and the Department of Home Affairs are unambiguous on this point, and the exceptions are narrow. Beyond that first check, reporting entities carry three ongoing duties: verify identity and beneficial ownership on reasonable grounds, monitor the relationship for change, and escalate to enhanced measures when risk demands it.


TL;DR:


Table of Contents

What is customer due diligence in Australia, and what must you establish first?

Customer due diligence Australia obligations require you to establish, on reasonable grounds, who your customer actually is before you act for them. That means identifying the customer, anyone acting on their behalf, and any beneficial owners standing behind the transaction. You also need to understand the nature and purpose of the relationship and form a view on the money laundering and terrorism financing (ML/TF) risk it presents.

Verification has to rely on reliable and independent data, not a customer’s say-so. Reporting entities must verify identity using reliable, independent data before providing the designated service, and records of that verification must be kept for an extended period following the end of the business relationship. In practice, this usually means:

Delayed initial CDD is permitted only in limited circumstances set out in the Rules, typically where the ML/TF risk is low and immediate verification would unreasonably interrupt ordinary business. If identity can’t be established on reasonable grounds, you don’t provide the service, and you consider whether a suspicious matter report is warranted.

How do you run ongoing customer due diligence and re-screening?

Ongoing customer due diligence (OCDD) is where most reporting entities lose momentum after the initial rush of onboarding. The obligation doesn’t stop once a file is opened. You must keep customer identification information current, monitor transactions against the profile you built at onboarding, and revisit the ML/TF risk rating whenever something changes.

A workable OCDD framework usually follows this sequence:

  1. Set a re-verification trigger list: change of beneficial owner, unusual transaction size, a new jurisdiction, or a lapsed identity document.
  2. Schedule automated re-screening against sanctions and politically exposed person (PEP) lists at a frequency matched to the customer’s risk rating.
  3. Give frontline staff a clear escalation path the moment a transaction or behaviour looks inconsistent with the customer’s stated purpose.
  4. Record every re-screening outcome, even a clean one, so the file shows continuous monitoring rather than a single point-in-time check.

Pro Tip: Build re-screening into your calendar rather than your memory. A missed annual re-screen on a long-standing client is one of the easiest gaps for an AUSTRAC reviewer to find.

When must you apply enhanced customer due diligence?

Enhanced customer due diligence (ECDD) isn’t optional once specific triggers arise. AUSTRAC requires enhanced CDD to be applied in specified high-risk circumstances, and reporting entities need documented procedures ready before, not after, a trigger fires.

The statutory triggers you need to build into your risk assessment include:

Proportionate enhanced measures typically mean source of funds or source of wealth checks, a deeper look at ownership layers behind a trust or corporate vehicle, and more frequent file reviews. Every ECDD decision, and the reasoning behind it, belongs in your AML/CTF policies, which must set out how you conduct ongoing customer due diligence. A reviewer who can’t see why enhanced measures were or weren’t applied will treat that as a gap, even if the underlying decision was sound.

What are your PEP and sanctions screening obligations?

Politically exposed persons carry higher inherent ML/TF risk because of the influence, and potential corruption exposure, that comes with public office. Identifying a PEP isn’t a one-off tick box. It requires screening against credible, regularly updated data sources and a documented decision on whether the relationship needs enhanced measures.

Practical screening obligations include:

Where a customer is designated for targeted financial sanctions, the obligation to act is immediate rather than something you schedule for the next compliance meeting. Delay in that scenario is itself a compliance failure, independent of anything else in the file.

How do you verify beneficial ownership for companies, trusts and SMSFs?

Identifying the entity isn’t the same as identifying its owners, and this is where many otherwise diligent files fall short. The obligation is to establish the natural persons who ultimately own or control the customer, and a company extract or ASIC search alone rarely gets you there.

For a company, that means tracing ownership through the share register to the natural persons at the top, including where holding companies stack on top of each other. For a trust, it means reading the trust deed to identify trustees, appointors, and beneficiaries with a meaningful entitlement, not just naming the trust itself. For a self-managed super fund, it means identifying the members and trustees, who are usually the same people but not always.

Pro Tip: Keep a copy of the specific deed pages you relied on, not just a summary. If AUSTRAC asks how you reached your conclusion, the underlying document is your evidence. Our beneficial ownership guide for trusts, SMSFs and companies walks through each structure in more depth.

Can you rely on another entity’s CDD checks?

Sections 37A and 38 of the AML/CTF Act allow one reporting entity to rely on customer due diligence already performed by another, which avoids duplicated checks on the same party across a single transaction. Relying on someone else’s work doesn’t transfer your legal responsibility, though. You remain accountable for the adequacy of the CDD you’re leaning on.

Before relying on another party’s checks, confirm:

  1. The other entity is itself a reporting entity subject to the AML/CTF Act, or an equivalent regulated status recognised under the Rules.
  2. The scope and date of their original verification actually cover the matters you need established.
  3. You can obtain the underlying verification evidence on request, not just a one-line assurance that “checks were done.”

Failing to verify the relying party’s regulated status and the standard of their original checks is a recurring compliance failure uncovered in reviews. Delayed initial CDD for pre-commencement customers follows the same logic: monitor the file closely until verification catches up.

What records must you keep, and for how long?

Every reporting entity must retain CDD records for seven years after the relationship ends, covering verification evidence, the risk rating assigned, and the reasoning behind any enhanced or simplified measures applied.

A tamper-evident audit trail matters as much as the records themselves. A reviewer trusts a file they can see wasn’t altered after the fact, and privacy obligations still apply to how you store and access that identity data.

When does CDD actually start in a property transaction?

The trigger is the start of the designated service, not settlement. A real estate agent’s CDD obligation begins when they’re instructed to act for a seller, not when the contract exchanges and certainly not on settlement day. Waiting until settlement is the single most common timing error we see in real estate compliance files.

Who you verify depends on who you’re acting for:

Cooperating firms in the same transaction can use reliance arrangements to avoid re-verifying a party someone else has already checked properly, and some firms pass the verification fee to the transaction party rather than absorbing it. Our detailed breakdown of when AML compliance actually starts in a transaction covers edge cases like off-market sales and deceased estates.

How does a dedicated platform operationalise your CDD program?

Person plugging in laptop charger on desk

Since the 2024 amendments your AML/CTF program has two parts, and they are not the old Part A and Part B. It is a business-wide ML/TF risk assessment under section 26C, and a set of AML/CTF policies that manage and mitigate the risks that assessment identifies. The two are supposed to describe the same reality, and in practice most inconsistencies AUSTRAC flags come from documents drafted separately and never reconciled.

AML Guard generates both from one linked set of answers, so the policy matches the risk assessment and the training manual matches both. Beyond documentation, the platform runs:

Our plain-English guide to AML/CTF programs walks through how the risk assessment and the policies fit together.

Three implementation traps compliance teams keep falling into

Diagram of three customer due diligence compliance traps

Identity checks alone aren’t customer due diligence. If you stop before tracing beneficial ownership, you’ve done half the job and left the harder half undocumented.

Simplified CDD without a written rationale traceable to your risk assessment invites challenge later. Record why the lower-risk treatment applied at the time, not just that it did.

Reliance arrangements fail quietly. Confirm the other party’s regulated status and the scope of their checks before you lean on them, every time.

AML Guard: built for Tranche 2 reporting entities

Real estate agencies, conveyancers, law firms, accounting practices and trust and company service providers are now squarely within scope of Tranche 2 obligations. Unlike a template pack you download once and hope stays current, AML Guard keeps your ML/TF risk assessment, AML/CTF policies, compliance action plan and training manual generated as one linked set, so they actually agree with each other when AUSTRAC asks. An officer approves each determination before CDD proceeds; the platform automates the lookups and the record keeping, not the judgement.

AML Guard compliance dashboard showing linked AML/CTF program documents

The platform runs identity verification with biometric liveness, traces beneficial owners through companies, trusts and SMSFs, screens against PEP and sanctions lists with ongoing re-screening, and keeps a seven-year tamper-evident audit trail behind every decision. It’s built specifically for AUSTRAC’s rules and the designated services listed in Table 5 and Table 6 of the Act, not adapted from an offshore compliance model. If your firm needs a working CDD program rather than another set of documents to interpret, book a demo with AML Guard and see how your tenant would be configured to your designated services and risk profile.

Sources

See How AML Guard Works

Tranche 2 obligations are now in force.
Book a 20-minute demo to see how AML Guard supports your compliance from the moment your designated service begins.

Book a Demo
This article is for general information purposes only and does not constitute legal advice. Firms should obtain independent professional advice on their specific AML/CTF obligations.
Last reviewed: 29 August 2026.